Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Grocy Project

First CVE: Oct 14, 2020Active for: 6 yearsTotal CVEs: 12
19.5
VTI Score
Low

Grocy Project maintains a single, focused open-source inventory and household-management application that occupies a modest but notably engaged position in the self-hosted and home-automation landscape. The recurring vulnerability surface centers on web-application input handling and session management, with durable signals in cross-site scripting, cross-site request forgery, forced browsing, and injection-class flaws that are characteristic of web frameworks handling untrusted user input. A meaningful share of the vendor's disclosures reach serious severity; live exploitation activity and current exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 92% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Grocy Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 14, 2020
5 years ago
Most Recent CVE
Jan 6, 2025
564 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-55074CRITICAL
The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370.
Jan 6, 20259.024NONO
CVE-2023-42270HIGH
Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).
Sep 15, 20238.824NONO
CVE-2023-48199HIGH
HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script execution. This occurs when user-su
Nov 15, 20237.823NONO
CVE-2024-55076HIGH
Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.
Jan 6, 20258.122NONO
CVE-2024-8370MEDIUM
A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the file /api/files/recipepictures/ of the component SVG File U
Sep 1, 20245.419NONO
CVE-2023-48198MEDIUM
A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy version <= 4.0.3 allows attackers to obtain a victim's cooki
Nov 15, 20235.419NONO
CVE-2023-48197MEDIUM
Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when the victim clicks on the "see
Nov 15, 20235.419NONO
CVE-2020-25454MEDIUM
Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the recipe.
Nov 18, 20205.418NONO
CVE-2024-55075MEDIUM
Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.
Jan 6, 20255.317NONO
CVE-2023-48866MEDIUM
A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3
Dec 4, 20235.417NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
67%
25%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (8.3%)
Network11 (91.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High1 (8.3%)
Unknown0 (0.0%)
User Interaction
None3 (25.0%)
Unknown0 (0.0%)
Required9 (75.0%)
Privileges Required
Low8 (66.7%)
High1 (8.3%)
None3 (25.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Grocy Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Grocy Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Grocy Project's Products

View all 3 CNAs →

Top CWEs